Skip to main content
Category: Supplier and Third-Party

ISO/IEC 27036

Simply put

ISO/IEC 27036 is a standard in the ISO/IEC 27000 family that provides guidance on managing information security in relationships with suppliers and other third parties. It is intended to help organizations address the security risks that arise when they rely on external providers for products or services. Because no external evidence was available for this entry, the specifics of its structure, parts, and content cannot be stated with confidence and should be verified against the published standard.

Formal definition

ISO/IEC 27036 is a guidance standard within the ISO/IEC 27000 series addressing information security for supplier and third-party relationships. It is positioned as supporting guidance rather than a certifiable management system standard; unlike ISO/IEC 27001 (whose ISMS requirements in clauses 4 through 10 are certifiable), ISO/IEC 27036 provides recommendations and would typically be applied to inform an organization's supplier-related risk treatment and controls. Practitioners should note that the precise scope, number of parts, and detailed content of ISO/IEC 27036 depend on the specific edition and cannot be asserted here, as no supporting evidence was provided; consult the current published version and relevant accredited sources before relying on any specific claim.

Why it matters

Most organizations depend on external suppliers, service providers, and other third parties for critical products and services, and each of those relationships can introduce information security risk that falls outside the organization's direct control. ISO/IEC 27036 matters because it provides structured guidance for addressing precisely this category of risk, helping organizations think systematically about how security expectations are set, communicated, and maintained across supplier relationships rather than leaving them to ad hoc arrangements.

For compliance and GRC teams, supplier security is a recurring theme across frameworks. In an ISO/IEC 27001 program, supplier-related risks are treated through the ISMS risk assessment and the selection of applicable controls via the Statement of Applicability, and guidance-oriented standards such as ISO/IEC 27036 can inform how those supplier controls are designed and applied. In a SOC 2 examination, third-party and vendor management considerations may be relevant depending on the scope and the Trust Services Criteria selected. Because ISO/IEC 27036 is guidance rather than a certifiable management system standard, it does not itself produce a certificate or an attestation report, and its value lies in shaping practice rather than in a formal audit outcome.

Because no external evidence was available for this entry, the specific structure, parts, and detailed content of ISO/IEC 27036 cannot be stated with confidence here. Practitioners should verify all specifics against the current published standard before relying on any particular claim about its requirements or scope.

Who it's relevant to

GRC and Compliance Managers
Those responsible for governance, risk, and compliance programs may look to ISO/IEC 27036 for guidance on structuring supplier and third-party security expectations. It can inform how vendor risk is assessed and treated, though it does not itself provide a certification or attestation outcome. Specifics should be confirmed against the published standard.
ISO 27001 Practitioners
Teams operating an ISMS under ISO/IEC 27001 may use ISO/IEC 27036 as supporting guidance when addressing supplier-related risks identified in their risk assessment and reflected in the Statement of Applicability. It complements, rather than replaces, the certifiable ISMS requirements in clauses 4 through 10.
SOC 2 Teams and Auditors
In engagements where vendor and third-party management is relevant to the selected Trust Services Criteria, practitioners may draw on supplier security guidance to shape controls. Note that a SOC 2 report attests only to the controls and period covered and is distinct from any guidance standard applied in designing those controls.
Procurement and Vendor Management Functions
Teams that establish and maintain supplier relationships may find ISO/IEC 27036 useful for embedding security considerations into how third-party arrangements are set up and monitored. Because the detailed content depends on the edition, the current published version should be consulted before operationalizing its recommendations.

Inside ISO/IEC 27036

Supplier relationship security guidance
ISO/IEC 27036 is a multi-part standard providing guidance on information security in supplier and acquirer relationships, addressing the risks that arise when organizations rely on external parties for products or services.
Multi-part structure
The standard is organized into several parts covering overview and concepts, general requirements, guidelines for information and communication technology supply chain security, and guidelines for the security of cloud services. The specific numbering and content of each part depend on the edition, so practitioners should confirm the current part structure against the published version.
Guidance rather than certifiable requirements
ISO/IEC 27036 is guidance-oriented and is not itself a certifiable management system standard in the way ISO/IEC 27001 (clauses 4 through 10) is. It supports supplier-related risk treatment rather than serving as a basis for certification.
Relationship to ISO/IEC 27001 supplier controls
The standard elaborates on supplier relationship topics that appear as reference controls in ISO/IEC 27001 Annex A, offering more detailed practices than the Annex A control statements alone. Which Annex A controls apply depends on an organization's Statement of Applicability and risk assessment.
Applicability across both sides of the relationship
It provides guidance for both acquirers (customers procuring products or services) and suppliers, addressing security expectations, obligations, and lifecycle management of the relationship.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27036.

Is ISO/IEC 27036 a certifiable standard like ISO/IEC 27001?
No. ISO/IEC 27036 is a guidance standard addressing information security for supplier relationships, not a management system standard against which an accredited certification body issues a certificate. Certification is achieved against ISO/IEC 27001, whose certifiable requirements sit in clauses 4 through 10. ISO/IEC 27036 can inform how an organization addresses supplier-related risks and controls, but you do not become 'certified to ISO/IEC 27036.' Any assurance over supplier security typically flows through the certified scope of an ISMS or through separate contractual and audit arrangements.
Does following ISO/IEC 27036 mean my third-party risk is covered for a SOC 2 examination?
Not automatically. A SOC 2 examination is an attestation performed by a licensed CPA firm under the AICPA's SSAE 18 standard and evaluates the controls and criteria within the defined scope over (for Type II) a review period whose length is set by scoping decisions. ISO/IEC 27036 guidance may help you design vendor management controls, but the SOC 2 report attests only to the controls and period covered, and the service auditor assesses those controls against the applicable Trust Services Criteria. Mapping between the two is partial, and using ISO/IEC 27036 guidance does not by itself satisfy any SOC 2 criterion.
How does ISO/IEC 27036 relate to Annex A controls when building an ISMS?
ISO/IEC 27036 provides more detailed guidance on supplier relationship security than the reference controls listed in ISO/IEC 27001 Annex A, which are selected via a Statement of Applicability informed by risk assessment. In most implementations, organizations use Annex A (as restructured in the 2022 revision, which reorganized reference controls into themes) to determine which supplier-related controls are applicable, then draw on ISO/IEC 27036 for practical implementation detail. The exact controls you select depend on your scope and risk assessment rather than any universal requirement.
At what point in a supplier engagement should ISO/IEC 27036 guidance be applied?
ISO/IEC 27036 addresses supplier relationships across their lifecycle, so its guidance is typically applied from initial supplier selection and agreement through ongoing management and eventual termination. In practice, organizations often align these activities with their existing ISMS processes so that supplier risk is assessed before onboarding, reflected in contractual terms, monitored during the relationship, and addressed at exit. The precise integration points depend on your scope and internal processes.
How should ISO/IEC 27036 inform contractual security requirements with vendors?
The guidance in ISO/IEC 27036 can help organizations articulate security expectations, roles, and responsibilities within supplier agreements. In most engagements, teams translate the relevant guidance into contractual clauses covering areas such as security requirements, monitoring, and incident handling, aligned to the risk associated with each supplier. Because outcomes depend on scope, applicable criteria, and the specific relationship, treat these as informed practices rather than mandatory templates, and validate them against your own risk assessment and legal review.
Can ISO/IEC 27036 help address supplier risk that appears in both my ISO 27001 ISMS and my SOC 2 scope?
It can support both, but through different mechanisms and without creating equivalence. For an ISO/IEC 27001 ISMS, ISO/IEC 27036 guidance can inform how you implement applicable supplier-related Annex A controls selected through your Statement of Applicability. For a SOC 2 examination, it may help you design vendor management controls that the service auditor then evaluates against the applicable Trust Services Criteria over the covered period. Satisfying supplier risk expectations in one framework does not automatically satisfy the other, and each remains limited to its own defined scope.

Common misconceptions

An organization can be certified against ISO/IEC 27036.
ISO/IEC 27036 is guidance and is not, in most editions, a certifiable standard. Certification in the ISO/IEC 27000 family is typically obtained against ISO/IEC 27001 by an accredited certification body; ISO/IEC 27036 supports supplier-relationship practices but does not on its own produce a certificate.
Implementing ISO/IEC 27036 satisfies SOC 2 vendor-management expectations automatically.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, evaluating controls against the applicable Trust Services Criteria. While supplier-management practices informed by ISO/IEC 27036 may support relevant controls, they are assessed independently by the service auditor and do not automatically satisfy SOC 2 criteria. Mapping between frameworks is partial.
ISO/IEC 27036 and ISO/IEC 27017/27018 cover the same thing.
These standards address related but distinct areas. ISO/IEC 27036 focuses on supplier relationship security broadly, while ISO/IEC 27017 and ISO/IEC 27018 provide cloud-specific security and privacy guidance. They can be complementary depending on scope, but they are separate documents and should not be treated as interchangeable.

Best practices

Confirm the current edition and part structure of ISO/IEC 27036 before citing specific content, since the parts and their scope depend on the published version.
Use ISO/IEC 27036 to elaborate on supplier-related reference controls selected in your ISO/IEC 27001 Statement of Applicability, driving control selection from your risk assessment rather than adopting all guidance wholesale.
Apply the guidance to both acquirer and supplier perspectives, clarifying security expectations and obligations across the full lifecycle of each relationship.
Where cloud services are involved, consider ISO/IEC 27017 and ISO/IEC 27018 alongside ISO/IEC 27036 rather than relying on any single standard for cloud-specific security and privacy topics.
If you also pursue a SOC 2 examination, map supplier-management practices to the applicable Trust Services Criteria explicitly, recognizing that alignment with one framework does not automatically satisfy the other.
Document how supplier-relationship guidance is operationalized so that both ISO 27001 certification bodies and SOC 2 service auditors can evaluate the design and, where relevant, operating effectiveness of the resulting controls within their defined scope and review period.